Just read his posts, half of the vulnerabilities he found involve non-public-facing PHP files; how does that make any sense? The original XSS one was closest to an exploit, but it's ridiculous since single quotes are never used for attributes anywhere in WHMCS source code (and to work the...